Certified Cloud Security Professional (CCSP)
Credential: Certified Cloud Security Professional (CCSP)
Credentialing Agency: International Information Systems Security Certification Consortium, Inc. (ISC)²
Renewal Period: 3 years
The International Information Systems Security Certification Consortium, Inc. ((ISC)2) Certified Cloud Security Professional (CCSP) credential is ideal for IT and information security leaders responsible for applying best practices to cloud security architecture, design, operations and service orchestration. Candidates must have a minimum of five years cumulative paid work experience in information technology, of which three years must be in information security and one year in one or more of the six domains of the CCSP CBK. Earning CSA’s CCSK certificate can be substituted for one year of experience in one or more of the six domains of the CCSP CBK. Earning (ISC)²’s CISSP credential can be substituted for the entire CCSP experience requirement.
More information can be found on the certifying agency's website.
Certified Cloud Security Professional (CCSP)
MINIMUM REQUIREMENTS
Attainability:
Eligibility Requirements (View Details)
- Credential Prerequisite
- Experience: 5 years
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for a Service member to meet eligibility requirements. Requirements listed here are based on the minimum degree required. To view other options, see the Eligibility tab.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
Exam Administration (View Details)
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
RECERTIFICATION SUMMARY
Renewal Period: 3 years
AGENCY CONTACT INFORMATION
International Information Systems Security Certification Consortium, Inc. (ISC)²
311 Park Place Blvd
Suite 400
Clearwater, FL 33759
Phone: (866) 331-4722
Fax: (703) 356-7977
Email: communications@isc2.org
Experience REQUIREMENTS
Candidates must have a minimum of five years cumulative paid work experience in information technology, of which three years must be in information security and one year in one or more of the six domains of the CCSP CBK. Earning CSA’s CCSK certificate can be substituted for one year of experience in one or more of the six domains of the CCSP CBK.
Option 2:Earning CSA’s CCSK certificate can be substituted for one year of experience in one or more of the six domains of the CCSP CBK.
Option 3:(ISC)²’s CISSP credential can be substituted for the entire CCSP experience requirement.
Other REQUIREMENTS
The Certified Cloud Security Professional (CCSP) credential has the following other requirements:
- Candidates must subscribe to the (ISC)2 Code of Ethics.
Written Exam
-
Cloud Concepts, Architecture and Design (17%)
- Understand Cloud Computing Concepts
- Describe Cloud Reference Architecture
- Understand Security Concepts Relevant to Cloud Computing
- Understand Design Principles of Secure Cloud Computing
- Evaluate Cloud Service Providers
-
Cloud Data Security (19%)
- Describe Cloud Data Concepts
- Design and Implement Cloud Data Storage Architectures
- Design and Apply Data Security Technologies and Strategies
- Implement Data Discovery
- Implement Data Classification
- Design and Implement Information Rights Management (IRM)
- Plan and Implement Data Retention, Deletion and Archiving Policies
- Design and Implement Auditability, Traceability and Accountability of Data Events
-
Cloud Platform & Infrastructure Security (17%)
- Comprehend Cloud Infrastructure Components
- Design a Secure Data Center
- Analyze Risks Associated with Cloud Infrastructure
- Design and Plan Security Controls
- Plan Disaster Recovery (DR) and Business Continuity (BC)
-
Cloud Application Security (17%)
- Advocate Training and Awareness for Application Security
- Describe the Secure Software Development Life Cycle (SDLC) Process
- Apply the Secure Software Development Life Cycle (SDLC)
- Apply Cloud Software Assurance and Validation
- Use Verified Secure Software
- Comprehend the Specifics of Cloud Application Architecture
- Design Appropriate Identity and Access Management (IAM) Solutions
-
Cloud Security Operations (17%)
- Implement and Build Physical and Logical Infrastructure for Cloud Environment
- Operate Physical and Logical Infrastructure for Cloud Environment
- Manage Physical and Logical Infrastructure for Cloud Environment
- Implement Operational Controls and Standards (e.g., Information Technology Infrastructure Library (ITIL), International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 20000-1)
- Support Digital Forensics
- Manage Communication with Relevant Parties
- Manage Security Operations
-
Legal, Risk and Compliance (13%)
- Articulate Legal Requirements and Unique Risks within the Cloud Environment
- Understand Privacy Issues
- Understand Audit Process, Methodologies, and Required Adaptations for a Cloud Environment
- Understand Implications of Cloud to Enterprise Risk Management
- Understand Outsourcing and Cloud Contract Design
Exam Preparation Resources
There are a number of resources available to help you prepare for the Certified Cloud Security Professional (CCSP) examination:
- Best Sources
- General References
- Related Courses
An additional resource is O'Reilly Learning Safari Books Online, a searchable digital library that provides online access to thousands of books, training videos and conference sessions. See the Educational Resources section on the Related Sites page here on COOL to learn how to get free access.
Testing Information
-
Exam Administration
Credential exams may be administered in-person at a testing site, proctored on-line remotely, or have options for both. If an exam is administered through a test vendor, the third-party test vendor box will be checked. The following test administration options apply to the Certified Cloud Security Professional (CCSP) credential where checked:
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
For more information on the International Information Systems Security Certification Consortium, Inc. (ISC)² testing process, visit the agency website.
-
Third-Party Test Vendor Information
Testing for this credential is handled by the following vendor:
Pearson VUE
The test centers are located in the U.S. They also have some test centers on military bases.
To find out more, use the following links on the Pearson VUE website:
- Search for Testing Program
- Learn About Testing for Military Communities
- Agency/Certification Specific Testing Information
- Contact Pearson VUE
RECERTIFICATION
Certified Cloud Security Professional (CCSP)
Renewal Period: 3 years
Additional considerations for the Certified Cloud Security Professional (CCSP) include:
- A candidate who doesn’t have the required experience to become a CCSP may become an Associate of (ISC)² by successfully passing the CCSP examination. The Associate of (ISC)² will then have six years to earn the five years required experience.